Inbound integrations
Enriching runZero results with data from other tools
runZero integrates with several sources of asset data so you can enrich your asset inventory and find assets and subnets that aren’t effectively managed or protected. Through product APIs and export/import functionality, runZero can pull data from many IT and security tools to extend visibility across your organization’s network.
Supported integrations
Cloud and virtualization
Endpoint protection
- CrowdStrike Falcon
- Microsoft 365 Defender
- Microsoft Intune
- Miradore MDM
- SentinelOne
- Tanium API Gateway
Endpoint management
Asset and identity management
- Google Workspace
- Microsoft Active Directory
- Microsoft Entra ID (formerly Azure AD)
Vulnerabilities and risk
Network management
Custom integrations
If runZero has no integration for the tool you want to draw data from, Platform and Community users can add asset data from custom sources with the custom integrations feature. The primary path is custom integration scripts, which run on your Explorers or on the console and can pull from REST APIs or directly over SSH, SMB, WinRM, WMI, and SQL. A library of over a hundred ready-to-use scripts is available in the runzero-custom-integrations repository and from the example picker in the console’s script editor. Where AI is enabled, the console can generate a script from a plain-language description. You can also import custom asset data through the API or the runZero Python SDK.
Each custom integration is available either to every organization in the account or only to the organizations granted access to it, and administrators can edit only the integrations that belong to organizations they administer. See organization access for details.
Scan probes or connector tasks
Most integrations can run either as a scan probe or as a connector task.
Scan probes run as part of a scan task, so one task can scan your environment and sync integrations at the same time. To run an integration as a scan probe:
- Configure a scan task from the Scan menu in your inventory or tasks page.
- Activate the integration under the Probes tab.
- Activate the correct credential under the Credentials tab.
- Configure, activate, or deactivate other scan task options as preferred.
Connector tasks run independently of scan tasks, so you can schedule integration syncs and asset scans separately. They run from the runZero cloud by default, or from an Explorer in your organization if you prefer. To run an integration as a connector task:
- Configure a connector task from the Integrations page or the Integrate menu in your inventory or tasks page.
- Select an Explorer from the Explorer menu (optional).
- Configure, activate, or deactivate other connector task options as preferred.
Importing integration data
Some integrations can be used by importing data from the other platform into runZero. For example, runZero ingests .nessus files from Tenable Nessus and .xml files from Rapid7 Nexpose without connecting to their APIs.
Automatic asset merge
runZero maps each integration host to an asset like this:
- If the host matches an existing runZero asset, runZero updates the asset-level attributes and adds the integration-specific attributes.
- If the host matches no existing runZero asset, runZero creates a new asset in the site you chose when you set up the integration task.
runZero matches integration data to existing assets by the following, in priority order:
- MAC address
- IP address (3-day window)
- Hostname
You can also merge integration assets into runZero assets by hand with the Merge button on the Asset Inventory page.
Removing an integration data source
When you remove an integration as a data source, runZero removes its attributes from your assets. Because some asset attribute fields are merged, attributes populated by both runZero scans and the integration may be deleted too. Rescanning the affected assets restores them.
Excluding integration attributes
You can configure your account and organizations to skip collecting certain integration attributes, for example personally identifiable information (PII) such as usernames or email addresses. Some attributes drive runZero’s merging and fingerprinting, though, and excluding them may make your inventory less accurate.
Set excluded attributes in your Account settings under Personally Identifiable Information (PII) collection to apply them across all organizations, or in the settings of an individual Organization to override the account-level settings.
You can use the default list of attributes or define your own. Attributes take the format @source.resourceType.attributeName. For example, @crowdstrike.dev.firstLoginUser excludes the attribute “firstLoginUser” from CrowdStrike devices.
Only integrations that import PII support attribute exclusions. At this time those are:
- CrowdStrike
- SentinelOne
- Tanium
- Google Workspace
- Intune
- Miradore
The Directory Users and Directory Groups inventories don’t support attribute exclusions. The AzureAD, LDAP, and Google Workspace integrations import directory users and groups by default, but you can turn that off in the task configuration.
Source names and IDs
This table maps each source name to the source ID you use when querying assets and vulnerabilities.
| ID | Name | Description |
|---|---|---|
| -1 | custom | Custom |
| 1 | runzero | runZero |
| 2 | miradore | Miradore |
| 3 | aws | AWS |
| 4 | crowdstrike | CrowdStrike |
| 5 | azure | Azure |
| 6 | censys | Censys |
| 7 | vmware | VMware |
| 8 | gcp | GCP |
| 9 | sentinelone | SentinelOne |
| 10 | tenable | Tenable |
| 11 | nessus | Nessus |
| 12 | rapid7 | Rapid7 |
| 13 | insightvm | InsightVM |
| 14 | qualys | Qualys |
| 15 | shodan | Shodan |
| 16 | azuread | AzureAD |
| 17 | ldap | LDAP |
| 18 | ms365defender | MS365Defender |
| 19 | intune | Intune |
| 20 | googleworkspace | GoogleWorkspace |
| 21 | sample | Sample |
| 22 | tenablesecuritycenter | TenableSecurityCenter |
| 23 | packet | Packet |
| 24 | wiz | Wiz |
| 25 | meraki | Meraki |
| 26 | mecm | MECM |
| 27 | tanium | Tanium |
| 28 | simulator | Simulator |
| 29 | netbox | NetBox |
| 30 | cip | CIP |
| 31 | pan | Palo Alto Networks |
| 32 | prisma | Prisma |
| 34 | dragos | Dragos |
| 35 | bacnet | BACnet |
| 36 | modbus | MODBUS |
| 37 | knxnet | KNXnet |
| 38 | insightvmcloud | InsightVMCloud |
| 39 | s7comm | S7comm |
| 40 | dnp3 | DNP3 |
| 41 | profinet | PROFINET |
| 42 | ethercat | EtherCAT |
| 43 | omronfins | OmronFINS |
| 44 | melsecq | MELSEC-Q |
| 45 | hartip | HART-IP |
| 46 | c37118 | C37.118 |
| 47 | ads | ADS |
| 48 | opcua | OPC-UA |
| 49 | s7 | S7 |
| 50 | iec104 | IEC60870-5-104 |
| 51 | mms | IEC61850-MMS |
| 52 | censysplatform | CensysPlatform |
| 10001 | tailscale | Tailscale |
| 10002 | ninjaone | NinjaOne |